SourceCodester Garage Management System(Cms-Website)是mayuri_k个人开发者的一个车库管理系统。可帮助您管理所有车辆、汽车和摩托车。 Garage Management System 1.0存在安全漏洞,该漏洞源于影响到文件/login.php的未知代码。通过输入特殊字符串对参数用户名进行操作会导致 sql 注入。该攻击可以远程发起。该漏洞已向公众披露并可能被使用。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| SourceCodester | Garage Management System | 1.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Garage Management System 1.0 contains a SQL injection vulnerability in /login.php via manipulation of the argument username with input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT. An attacker can possibly obtain sensitive information from a database, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2467.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论